Vulnerabilities CISA has confirmed as actively exploited. Prioritize these for remediation.
Vulnerabilities newly added to CISA KEV in the last 7 days.
| CVE ID | Title | Severity | Added |
|---|---|---|---|
| Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. | CRITICAL | 2026. 07. 16. | |
| A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests | CRITICAL |
| CVE ID | Title | Severity | References | Ransom | |||||
|---|---|---|---|---|---|---|---|---|---|
| Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability | HIGH | 7.8v3.1 | 100 | 9.8% |
| 2026. 07. 16. |
| CVE-2026-39808 | A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector here> | CRITICAL | 2026. 07. 16. |
| CVE-2026-46817 | Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C | CRITICAL | 2026. 07. 15. |
| CVE-2023-4346 | KNX devices that use KNX Connection Authorization and support Option 1 are, depending on the implementation, vulnerable to being locked and users being unable to reset them to gain access to the device. The BCU key feature on the devices can be used to create a password for the device, but this password can often not be reset without entering the current password. If the device is configured to interface with a network, an attacker with access to that network could interface with the KNX instal | HIGH | 2026. 07. 15. |
KEV KISA |
| 2025. 01. 14. |
| 2025. 01. 14. |
| — |
| CVE-2024-55591 | An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 allows a remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module. | CRITICAL | 9.8v3.1 | 100 | 98.3% | KEV KISA | 2025. 01. 14. | 2025. 01. 14. | ⚠️ |
| CVE-2024-12686 | A vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) which can allow an attacker with existing administrative privileges to inject commands and run as a site user. | MEDIUM | 6.6v3.1 | 99 | 13.8% | KEV | 2024. 12. 18. | 2025. 01. 13. | — |
| CVE-2023-48365 | Qlik Sense Enterprise for Windows before August 2023 Patch 2 allows unauthenticated remote code execution, aka QB-21683. Due to improper validation of HTTP headers, a remote attacker is able to elevate their privilege by tunneling HTTP requests, allowing them to execute HTTP requests on the backend server that hosts the repository application. The fixed versions are August 2023 Patch 2, May 2023 Patch 6, February 2023 Patch 10, November 2022 Patch 12, August 2022 Patch 14, May 2022 Patch 16, Feb | CRITICAL | 9.6v3.1 | 100 | 24.7% | KEV KISA | 2023. 11. 15. | 2025. 01. 13. | ⚠️ |
| CVE-2025-0282 | A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a remote unauthenticated attacker to achieve remote code execution. | CRITICAL | 9.0v3.1 | 100 | 100.0% | KEV KISA | 2025. 01. 08. | 2025. 01. 08. | ⚠️ |
| CVE-2024-55550 | Mitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative privilege to conduct a local file read, due to insufficient input sanitization. A successful exploit could allow the authenticated admin attacker to access resources that are constrained to the admin access level, and the disclosure is limited to non-sensitive system information. This vulnerability does not allow file modification or privilege escalation. | LOW | 2.7v3.1 | 45.50 | 38.1% | KEV | 2024. 12. 10. | 2025. 01. 07. | ⚠️ |
| CVE-2024-41713 | A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct a path traversal attack, due to insufficient input validation. A successful exploit could allow unauthorized access, enabling the attacker to view, corrupt, or delete users' data and system configurations. | CRITICAL | 9.1v3.1 | 100 | 98.1% | KEV | 2024. 10. 21. | 2025. 01. 07. | ⚠️ |
| CVE-2020-2883 | — | — | — | 82.50 | 94.9% | KEV | — | 2025. 01. 07. | — |
| CVE-2024-3393 | A Denial of Service vulnerability in the DNS Security feature of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to send a malicious packet through the data plane of the firewall that reboots the firewall. Repeated attempts to trigger this condition will cause the firewall to enter maintenance mode. | HIGH | 8.7v4.0 | 100 | 26.6% | KEV KISA | 2024. 12. 27. | 2024. 12. 30. | — |
| CVE-2021-44207 | — | — | — | 82.50 | 17.6% | KEV | — | 2024. 12. 23. | — |
| CVE-2024-12356 | A critical vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) products which can allow an unauthenticated attacker to inject commands that are run as a site user. | CRITICAL | 9.8v3.1 | 100 | 88.0% | KEV | 2024. 12. 17. | 2024. 12. 19. | — |
| CVE-2018-14933 | upgrade_handle.php on NUUO NVRmini devices allows Remote Command Execution via shell metacharacters in the uploaddir parameter for a writeuploaddir command. | CRITICAL | 9.8v3.1 | 100 | 93.7% | KEV | 2018. 08. 04. | 2024. 12. 18. | — |
| CVE-2022-23227 | — | — | — | 82.50 | 49.4% | KEV | — | 2024. 12. 18. | — |
| CVE-2019-11001 | — | — | — | 82.50 | 38.4% | KEV | — | 2024. 12. 18. | — |
| CVE-2021-40407 | — | — | — | 82.50 | 47.9% | KEV | — | 2024. 12. 18. | — |
| CVE-2024-55956 | In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can import and execute arbitrary Bash or PowerShell commands on the host system by leveraging the default settings of the Autorun directory. | CRITICAL | 9.8v3.1 | 100 | 93.8% | KEV | 2024. 12. 13. | 2024. 12. 17. | ⚠️ |
| CVE-2024-35250 | Windows Kernel-Mode Driver Elevation of Privilege Vulnerability | HIGH | 7.8v3.1 | 100 | 25.2% | KEV KISA | 2024. 06. 11. | 2024. 12. 16. | — |
| CVE-2024-20767 | — | — | — | 82.50 | 98.5% | KEV | — | 2024. 12. 16. | — |
| CVE-2024-50623 | In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download that could lead to remote code execution. | CRITICAL | 9.8v3.1 | 100 | 98.5% | KEV | 2024. 10. 28. | 2024. 12. 13. | ⚠️ |
| CVE-2024-49138 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | HIGH | 7.8v3.1 | 100 | 25.4% | KEV KISA | 2024. 12. 12. | 2024. 12. 10. | — |